mirror of
https://github.com/moby/moby.git
synced 2022-11-09 12:21:53 -05:00
Add SYS_CHROOT cap to unprivileged containers
Fixes #6103 Docker-DCO-1.1-Signed-off-by: Michael Crosby <michael@crosbymichael.com> (github: crosbymichael)
This commit is contained in:
parent
f65fadbda0
commit
41f7cef2bd
2 changed files with 13 additions and 0 deletions
|
@ -20,6 +20,7 @@ func New() *libcontainer.Container {
|
|||
"SETFCAP",
|
||||
"SETPCAP",
|
||||
"NET_BIND_SERVICE",
|
||||
"SYS_CHROOT",
|
||||
},
|
||||
Namespaces: map[string]bool{
|
||||
"NEWNS": true,
|
||||
|
|
|
@ -873,3 +873,15 @@ func TestThatCharacterDevicesActLikeCharacterDevices(t *testing.T) {
|
|||
|
||||
logDone("run - test that character devices work.")
|
||||
}
|
||||
|
||||
func TestRunUnprivilegedWithChroot(t *testing.T) {
|
||||
cmd := exec.Command(dockerBinary, "run", "busybox", "chroot", "/", "true")
|
||||
|
||||
if _, err := runCommand(cmd); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
deleteAllContainers()
|
||||
|
||||
logDone("run - unprivileged with chroot")
|
||||
}
|
||||
|
|
Loading…
Add table
Reference in a new issue